Search

Found 600 results in 99ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2014-0437 low 3.5 debian debianubuntu ubuntu rhel oraclemariadb 13y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote authenticated users to affect availability via unk…
CVE-2014-0420 low 2.8 debian debianubuntu ubuntu rhel oraclemariadb 13y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.34 and earlier, and 5.6.14 and earlier, allows remote authenticated users to affect availability via unknown vectors relate…
CVE-2014-0393 low 3.3 debian debianubuntu ubuntu rhel oraclemariadb 13y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.71 and earlier, 5.5.33 and earlier, and 5.6.13 and earlier allows remote authenticated users to affect integrity via unknow…
CVE-2013-5908 low 2.6 debian debianubuntu ubuntu rhel oraclemariadb 13y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote attackers to affect availability via unknown vecto…
CVE-2013-4969 low 2.1 FIX slesdebian debianubuntu ubuntu puppetlabspuppet 13y ago Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified files.
CVE-2013-5619 high 7.5 fedora fedorasuse suseubuntu ubuntu mozilla 13y ago Multiple integer overflows in the binary-search implementation in SpiderMonkey in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 might allow remote attackers to cause a denial of service (out-…
CVE-2013-6410 high 7.5 FIX ubuntu ubuntudebian debian wouter_verhelst 13y ago nbd-server in Network Block Device (nbd) before 3.5 does not properly check IP addresses, which might allow remote attackers to bypass intended access restrictions via an IP address that has a partia…
CVE-2012-6150 low 3.6 FIX ubuntu ubuntudebian debian samba 13y ago The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which all…
CVE-2013-4459 low 3.3 FIX debian debianubuntu ubuntu robert_ancell 13y ago LightDM 1.7.5 through 1.8.3 and 1.9.x before 1.9.2 does not apply the AppArmor profile to the Guest account, which allows local users to bypass intended restrictions by leveraging the Guest account.
CVE-2013-4473 high 7.5 FIX ubuntu ubuntudebian debian freedesktop 13y ago Stack-based buffer overflow in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary c…
CVE-2013-4588 high 7.0 7.0 FIX ubuntu ubuntu linux-kerneldebian debian 13y ago Multiple stack-based buffer overflows in net/netfilter/ipvs/ip_vs_ctl.c in the Linux kernel before 2.6.33, when CONFIG_IP_VS is used, allow local users to gain privileges by leveraging the CAP_NET_AD…
CVE-2013-4563 high 7.1 FIX ubuntu ubuntudebian debian linux-kernel 13y ago The udp6_ufo_fragment function in net/ipv6/udp_offload.c in the Linux kernel through 3.12, when UDP Fragmentation Offload (UFO) is enabled, does not properly perform a certain size comparison before …
CVE-2013-4348 high 7.1 FIX debian debian linux-kernelubuntu ubuntu 13y ago The skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel through 3.12 allows remote attackers to cause a denial of service (infinite loop) via a small value in the IHL field of …
CVE-2013-1056 low 1.9 FIX ubuntu ubuntudebian debian 13y ago X.org X server 1.13.3 and earlier, when not run as root, allows local users to cause a denial of service (crash) or possibly gain privileges via vectors involving cached xkb files.
CVE-2013-4428 low 3.5 FIX debian debianubuntu ubuntu openstack 13y ago OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly restrict access to ca…
CVE-2013-4344 high 7.2 FIX slesubuntu ubuntu rhel qemuredhat 13y ago Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a R…
CVE-2013-4288 high 7.2 FIX slesubuntu ubuntu rhel polkit_project 13y ago Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is perf…
CVE-2013-5745 high 8.1 EXPFIX ubuntu ubuntudebian debian david_king 13y ago The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, does not properly clear client data when an error …
CVE-2013-4242 low 1.9 ubuntu ubuntususe susedebian debian gnupg 13y ago GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cach…
CVE-2013-2162 low 1.9 ubuntu ubuntu 13y ago Race condition in the post-installation script (mysql-server-5.5.postinst) for MySQL Server 5.5 for Debian GNU/Linux and Ubuntu Linux creates a configuration file with world-readable permissions befo…
CVE-2013-2126 high 7.5 FIX debian debianubuntu ubuntususe suse libraw 13y ago Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a denial of service (application crash) and po…
CVE-2013-2112 high 7.8 FIX ubuntu ubuntususe susedebian debian apachecollabnet 13y ago The svnserve server in Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote attackers to cause a denial of service (exit) by aborting a connection.
CVE-2013-4002 high 7.1 linux-kernelubuntu ubuntususe suse ibmoracleapache 13y ago Missing XML Validation in Apache Xerces2
CVE-2013-3812 low 3.5 debian debianubuntu ubuntususe suse oraclemariadb 13y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related …
CVE-2013-1943 high 7.8 7.8 FIX linux-kerneldebian debian rhel 13y ago The KVM subsystem in the Linux kernel before 3.0 does not check whether kernel addresses are specified during allocation of memory slots for use in a guest's physical address space, which allows loca…
CVE-2013-1059 high 7.8 FIX debian debian linux-kernelubuntu ubuntu 13y ago net/ceph/auth_none.c in the Linux kernel through 3.10 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an…
CVE-2013-1940 low 2.1 FIX ubuntu ubuntudebian debian x 13y ago X.Org X server before 1.13.4 and 1.4.x before 1.14.1 does not properly restrict access to input events when adding a new hot-plug device, which might allow physically proximate attackers to obtain se…
CVE-2013-1900 high 8.5 ubuntu ubuntu postgresql 13y ago PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, and 8.4.x before 8.4.17, when using OpenSSL, generates insufficiently random numbers, which might allow remote authenticated us…
CVE-2012-6129 high 7.5 FIX ubuntu ubuntufedora fedoradebian debian transmissionbt 13y ago Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute ar…
CVE-2013-1052 high 7.2 ubuntu ubuntu 13y ago pam-xdg-support, as used in Ubuntu 12.10, does not properly handle the PATH environment variable, which allows local users to gain privileges via unspecified vectors related to sudo.
CVE-2013-1653 high 7.1 FIX ubuntu ubuntudebian debian puppetpuppetlabs 13y ago Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, when listening for incoming connections is enabled and allowing access to…
CVE-2013-0249 high 8.5 EXPFIX debian debianubuntu ubuntu haxx 13y ago Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7.26.0 through 7.28.1, when negotiating SASL DIGEST-MD5 authentication, allows r…
CVE-2013-0894 high 7.5 FIX debian debian linux-kernelsuse suse googleffmpeg 14y ago Buffer overflow in the vorbis_parse_setup_hdr_floors function in the Vorbis decoder in vorbisdec.c in libavcodec in FFmpeg through 1.1.3, as used in Google Chrome before 25.0.1364.97 on Windows and L…
CVE-2013-0241 low 2.1 FIX ubuntu ubuntu rheldebian debian 14y ago The QXL display driver in QXL Virtual GPU 0.1.0 allows local users to cause a denial of service (guest crash or hang) via a SPICE connection that prevents other threads from obtaining the qemu_mutex …
CVE-2012-5689 high 7.1 FIX debian debianubuntu ubuntu rhel isc 14y ago ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS64 with a Response Policy Zone that lacks an AAAA rewrite rule, allows remote attackers to cause a d…
CVE-2012-5096 low 3.5 ubuntu ubuntu oraclemariadb 14y ago Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users with Server Privileges to affect availability via unknown vectors.
CVE-2012-5688 high 7.8 FIX debian debianubuntu ubuntu isc 14y ago ISC BIND 9.8.x before 9.8.4-P1 and 9.9.x before 9.9.2-P1, when DNS64 is enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.
CVE-2012-3515 high 7.2 FIX suse suse rheldebian debian qemuredhat 14y ago Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users to gain privileges via a crafted escape VT100 seq…
CVE-2012-5836 high 7.5 ubuntu ubuntususe suse mozilla 14y ago Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving…
CVE-2012-5830 high 8.8 8.8 macos macosubuntu ubuntususe suse mozillasuse 14y ago Use-after-free vulnerability in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 on Mac OS X allow…
CVE-2012-3197 low 3.5 rhelubuntu ubuntudebian debian oraclemariadb 14y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect availability via unknown vectors relate…
CVE-2012-3167 low 3.5 rhelubuntu ubuntudebian debian oraclemariadb 14y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors relate…
CVE-2012-3160 low 2.1 rhelubuntu ubuntudebian debian oraclemariadb 14y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5.27 and earlier, allows local users to affect confidentiality via unknown vectors related to Server …
CVE-2012-3158 high 7.5 rhelubuntu ubuntudebian debian oraclemariadb 14y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via …
CVE-2012-3412 high 7.8 FIX linux-kernelubuntu ubuntudebian debian 14y ago The sfc (aka Solarflare Solarstorm) driver in the Linux kernel before 3.2.30 allows remote attackers to cause a denial of service (DMA descriptor consumption and network-controller outage) via crafte…
CVE-2012-3400 high 7.6 FIX linux-kernelubuntu ubuntudebian debian 14y ago Heap-based buffer overflow in the udf_load_logicalvol function in fs/udf/super.c in the Linux kernel before 3.4.5 allows remote attackers to cause a denial of service (system crash) or possibly have …
CVE-2012-3955 high 7.1 FIX ubuntu ubuntudebian debian isc 14y ago ISC DHCP 4.1.x before 4.1-ESV-R7 and 4.2.x before 4.2.4-P2 allows remote attackers to cause a denial of service (daemon crash) in opportunistic circumstances by establishing an IPv6 lease in an envir…
CVE-2012-2665 high 7.5 FIX ubuntu ubuntudebian debian rhel apachelibreoffice 14y ago Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and po…
CVE-2012-3954 low 3.3 FIX debian debianubuntu ubuntu isc 14y ago Multiple memory leaks in ISC DHCP 4.1.x and 4.2.x before 4.2.4-P1 and 4.1-ESV before 4.1-ESV-R6 allow remote attackers to cause a denial of service (memory consumption) by sending many requests.
CVE-2011-4409 high 7.5 ubuntu ubuntu 14y ago The Ubuntu One Client for Ubuntu 10.04 LTS, 11.04, 11.10, and 12.04 LTS does not properly validate SSL certificates, which allows remote attackers to spoof a server and modify or read sensitive infor…
CVE-2012-0948 low 2.1 ubuntu ubuntu gnome 14y ago DistUpgrade/DistUpgradeMain.py in Update Manager, as used by Ubuntu 12.04 LTS, 11.10, and 11.04, uses weak permissions for (1) apt-clone_system_state.tar.gz and (2) system_state.tar.gz, which allows …
CVE-2012-1610 high 7.5 7.5 FIX debian debiansuse suseubuntu ubuntu imagemagick 14y ago Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-4 allows remote attackers to cause a denial of service (out-of-bounds read) via a large component cou…
CVE-2012-1185 high 7.8 7.8 FIX debian debiansuse suseubuntu ubuntu imagemagick 14y ago Multiple integer overflows in (1) magick/profile.c or (2) magick/property.c in ImageMagick 6.7.5 and earlier allow remote attackers to cause a denial of service (memory corruption) and possibly execu…
CVE-2012-0247 high 8.8 8.8 FIX debian debian rhelubuntu ubuntu imagemagickredhat 14y ago ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset and count values in the ResolutionUnit …
CVE-2012-0044 high 7.8 7.8 FIX linux-kernelubuntu ubuntu 14y ago Integer overflow in the drm_mode_dirtyfb_ioctl function in drivers/gpu/drm/drm_crtc.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 3.1.5 allows local users to gain privi…
CVE-2011-4405 high 7.5 FIX ubuntu ubuntudebian debian 15y ago The cupshelpers scripts in system-config-printer in Ubuntu 11.04 and 11.10, as used by the automatic printer driver download service, uses an "insecure connection" for queries to the OpenPrinting dat…
CVE-2011-2189 high 7.5 8.5 EXPFIX linux-kernel rhelubuntu ubuntu 15y ago net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate of creation and cleanup of network namespaces, which makes it easier for remote attackers to cause…
CVE-2011-3192 high 8.8 EXPFIX debian debianubuntu ubuntususe suse apache 15y ago The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range head…
CVE-2011-2749 high 7.8 FIX ubuntu ubuntudebian debian isc 15y ago The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial of service (daemon exit) via a crafted BOOTP packet.
CVE-2011-2748 high 7.8 FIX ubuntu ubuntudebian debian isc 15y ago The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial of service (daemon exit) via a crafted DHCP packet.
CVE-2011-2694 low 2.6 FIX ubuntu ubuntudebian debian samba 15y ago Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to …
CVE-2010-4656 high 7.8 7.8 FIX linux-kernelubuntu ubuntu 15y ago The iowarrior_write function in drivers/usb/misc/iowarrior.c in the Linux kernel before 2.6.37 does not properly allocate memory, which might allow local users to trigger a heap-based buffer overflow…
CVE-2011-2692 high 8.8 8.8 fedora fedoradebian debianubuntu ubuntu libpng 15y ago The png_handle_sCAL function in pngrutil.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 does not properly handle invalid sCAL chunks, which allows re…
CVE-2011-2690 high 8.8 8.8 fedora fedoradebian debianubuntu ubuntu libpng 15y ago Buffer overflow in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4, when used by an application that calls the png_rgb_to_gray function but not the png_set…
CVE-2011-0463 low 2.1 linux-kernelubuntu ubuntu 15y ago The ocfs2_prepare_page_for_write function in fs/ocfs2/aops.c in the Oracle Cluster File System 2 (OCFS2) subsystem in the Linux kernel before 2.6.39-rc1 does not properly handle holes that cross page…
CVE-2011-0997 high 7.5 FIX debian debianubuntu ubuntu isc 15y ago dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute arbitrary commands via shell metacharacters in a …
CVE-2011-1017 high 7.2 FIX linux-kernelubuntu ubuntu 16y ago Heap-based buffer overflow in the ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel 2.6.37.2 and earlier might allow local users to gain privileges or obtain sensitive information via …
CVE-2011-0712 high 7.2 FIX linux-kernelubuntu ubuntu 16y ago Multiple buffer overflows in the caiaq Native Instruments USB audio functionality in the Linux kernel before 2.6.38-rc4-next-20110215 might allow attackers to cause a denial of service or possibly ha…
CVE-2010-3850 low 3.1 EXPFIX linux-kernelsuse susedebian debian 16y ago The ec_dev_ioctl function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2 does not require the CAP_NET_ADMIN capability, which allows local users to bypass intended access restrictions …
CVE-2010-3861 low 2.1 FIX linux-kernelsuse suseubuntu ubuntu 16y ago The ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize a certain block of heap memory, which allows local users to obtain potentially sensitive inf…
CVE-2010-4072 low 1.9 FIX linux-kernelsuse susedebian debian 16y ago The copy_shmid_to_user function in ipc/shm.c in the Linux kernel before 2.6.37-rc1 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from k…
CVE-2010-3705 high 8.3 FIX linux-kernelfedora fedoraubuntu ubuntu 16y ago The sctp_auth_asoc_get_hmac function in net/sctp/auth.c in the Linux kernel before 2.6.36 does not properly validate the hmac_ids array of an SCTP peer, which allows remote attackers to cause a denia…
CVE-2010-2962 high 7.2 FIX linux-kernelsuse susefedora fedora 16y ago drivers/gpu/drm/i915/i915_gem.c in the Graphics Execution Manager (GEM) in the Intel i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.36 does not properly va…
CVE-2010-3432 high 7.8 FIX linux-kerneldebian debiansuse suse 16y ago The sctp_packet_config function in net/sctp/output.c in the Linux kernel before 2.6.35.6 performs extraneous initializations of packet data structures, which allows remote attackers to cause a denial…
CVE-2010-3702 high 7.5 FIX debian debiansuse susefedora fedora applefreedesktopxpdfreader 16y ago The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent atta…
CVE-2010-3298 low 2.1 FIX ubuntu ubuntususe suse linux-kernel 16y ago The hso_get_count function in drivers/net/usb/hso.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensi…
CVE-2010-3297 low 2.1 FIX ubuntu ubuntususe suse linux-kernel 16y ago The eql_g_master_cfg function in drivers/net/eql.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensit…
CVE-2010-3296 low 2.1 FIX ubuntu ubuntususe suse linux-kernel 16y ago The cxgb_extension_ioctl function in drivers/net/cxgb3/cxgb3_main.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain p…
CVE-2010-2943 high 8.1 9.1 EXPFIX ubuntu ubuntu linux-kernel avaya 16y ago The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read…
CVE-2010-2537 high 7.1 7.1 FIX ubuntu ubuntususe suse linux-kernel 16y ago The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a (1) BTRFS_IOC_CLONE or (2) BTRFS_IOC_CLONE_RANGE ioctl c…
CVE-2010-3310 low 1.9 ubuntu ubuntu linux-kerneldebian debian 16y ago Multiple integer signedness errors in net/rose/af_rose.c in the Linux kernel before 2.6.36-rc5-next-20100923 allow local users to cause a denial of service (heap memory corruption) or possibly have u…
CVE-2010-3084 high 7.2 ubuntu ubuntu linux-kernel 16y ago Buffer overflow in the niu_get_ethtool_tcam_all function in drivers/net/niu.c in the Linux kernel before 2.6.36-rc4 allows local users to cause a denial of service or possibly have unspecified other …
CVE-2010-2946 low 2.1 FIX ubuntu ubuntu linux-kernel 16y ago fs/jfs/xattr.c in the Linux kernel before 2.6.35.2 does not properly handle a certain legacy format for storage of extended attributes, which might allow local users by bypass intended xattr namespac…
CVE-2010-2478 high 7.2 FIX ubuntu ubuntususe suse linux-kernel 16y ago Integer overflow in the ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.33.7 on 32-bit platforms allows local users to cause a denial of service or possibly have unspe…
CVE-2010-1773 high 8.8 8.8 rhelubuntu ubuntususe suse google 16y ago Off-by-one error in the toAlphabetic function in rendering/RenderListMarker.cpp in WebCore in WebKit before r59950, as used in Google Chrome before 5.0.375.70, allows remote attackers to obtain sensi…
CVE-2010-1772 high 8.8 8.8 rhelubuntu ubuntususe suse google 16y ago Use-after-free vulnerability in page/Geolocation.cpp in WebCore in WebKit before r59859, as used in Google Chrome before 5.0.375.70, allows remote attackers to execute arbitrary code or cause a denia…
CVE-2010-3301 high 8.2 EXPFIX linux-kernelubuntu ubuntu 16y ago The IA32 system call emulation functionality in arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.36-rc4-git2 on the x86_64 platform does not zero extend the %eax register after the 32-bit ent…
CVE-2010-3477 low 2.1 FIX linux-kernelubuntu ubuntudebian debian 16y ago The tcf_act_police_dump function in net/sched/act_police.c in the actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc4 does not properly initialize certa…
CVE-2010-3080 high 7.2 FIX linux-kernelubuntu ubuntususe suse 16y ago Double free vulnerability in the snd_seq_oss_open function in sound/core/seq/oss/seq_oss_init.c in the Linux kernel before 2.6.36-rc4 might allow local users to cause a denial of service or possibly …
CVE-2010-3069 high 7.5 FIX ubuntu ubuntudebian debian samba 16y ago Stack-based buffer overflow in the (1) sid_parse and (2) dom_sid_parse functions in Samba before 3.5.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code…
CVE-2010-2960 high 7.8 7.8 FIX linux-kernelubuntu ubuntususe suse 16y ago The keyctl_session_to_parent function in security/keys/keyctl.c in the Linux kernel 2.6.35.4 and earlier expects that a certain parent session keyring exists, which allows local users to cause a deni…
CVE-2010-2955 low 2.1 FIX linux-kernelubuntu ubuntususe suse 16y ago The cfg80211_wext_giwessid function in net/wireless/wext-compat.c in the Linux kernel before 2.6.36-rc3-next-20100831 does not properly initialize certain structure members, which allows local users …
CVE-2010-2798 high 7.8 7.8 FIX linux-kerneldebian debianubuntu ubuntu avaya 16y ago The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local user…
CVE-2010-2524 high 7.8 7.8 FIX linux-kernelubuntu ubuntususe suse 16y ago The DNS resolution functionality in the CIFS implementation in the Linux kernel before 2.6.35, when CONFIG_CIFS_DFS_UPCALL is enabled, relies on a user's keyring for the dns_resolver upcall in the ci…
CVE-2010-2226 low 2.1 FIX linux-kerneldebian debianubuntu ubuntu 16y ago The xfs_swapext function in fs/xfs/xfs_dfrag.c in the Linux kernel before 2.6.35 does not properly check the file descriptors passed to the SWAPEXT ioctl, which allows local users to leverage write a…
CVE-2010-2008 low 4.5 EXP ubuntu ubuntufedora fedora oracle 16y ago MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (server crash and database loss) via an ALTER DATABASE command with a #mysql50# strin…
CVE-2010-2063 high 8.5 EXPFIX ubuntu ubuntudebian debian samba 16y ago Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 allows remote attackers to cause a denial of service (memory c…
CVE-2010-0050 high 8.8 9.8 EXPFIX ubuntu ubuntufedora fedoramacos macos apple 17y ago Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML document with improp…
CVE-2010-0302 high 7.5 7.5 FIX debian debianubuntu ubuntufedora fedora apple 17y ago Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epol…
CVE-2010-0650 low 2.6 ubuntu ubuntu googleapple 17y ago WebKit, as used in Google Chrome before 4.0.249.78 and Apple Safari, allows remote attackers to bypass intended restrictions on popup windows via crafted use of a mouse click event.